Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-5381

Опубликовано: 19 фев. 2018
Источник: ubuntu
Приоритет: medium
CVSS2: 5
CVSS3: 6.5

Описание

The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BGP OPEN messages, in the bgp_packet.c:bgp_capability_msg_parse function. The parser can enter an infinite loop on invalid capabilities if a Multi-Protocol capability does not have a recognized AFI/SAFI, causing a denial of service.

РелизСтатусПримечание
artful

released

1.1.1-3ubuntu0.2
devel

released

1.2.2-1ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [0.99.22.4-3ubuntu1.5]]
esm-infra/xenial

released

0.99.24.1-2ubuntu1.4
precise/esm

DNE

trusty

released

0.99.22.4-3ubuntu1.5
trusty/esm

DNE

trusty was released [0.99.22.4-3ubuntu1.5]
upstream

released

1.2.3
xenial

released

0.99.24.1-2ubuntu1.4

Показывать по

5 Medium

CVSS2

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
почти 8 лет назад

The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BGP OPEN messages, in the bgp_packet.c:bgp_capability_msg_parse function. The parser can enter an infinite loop on invalid capabilities if a Multi-Protocol capability does not have a recognized AFI/SAFI, causing a denial of service.

CVSS3: 6.5
nvd
почти 8 лет назад

The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BGP OPEN messages, in the bgp_packet.c:bgp_capability_msg_parse function. The parser can enter an infinite loop on invalid capabilities if a Multi-Protocol capability does not have a recognized AFI/SAFI, causing a denial of service.

CVSS3: 6.5
debian
почти 8 лет назад

The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its p ...

CVSS3: 7.5
github
больше 3 лет назад

The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BGP OPEN messages, in the bgp_packet.c:bgp_capability_msg_parse function. The parser can enter an infinite loop on invalid capabilities if a Multi-Protocol capability does not have a recognized AFI/SAFI, causing a denial of service.

suse-cvrf
почти 8 лет назад

Security update for quagga

5 Medium

CVSS2

6.5 Medium

CVSS3